CVE-2014-9708: Embedthis Appweb
Medium severity, CVSS 5.0. EPSS: 56.2% chance of exploitation in the next 30 days.
Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".
Affected products
- Embedthis Appweb: before 4.6.6 (fixed in 4.6.6); from 5.0.0, before 5.2.1 (fixed in 5.2.1)
- Juniper Junos: version 12.1x46 only; version 12.3x48 only; version 15.1x49 only; version 12.3 only; version 15.1 only; version 15.1x53 only; …
- Oracle Enterprise Communications Broker: up to and including 2.0.0
Published 2015-03-31. Last modified 2026-06-17.